IP Library Granted Patent US 9,992,170
Granted Patent B2
US 9,992,170 · App. 13/915,081 · Granted Jun 5, 2018

Secure data parser method and system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,992,170
App. No.
13/915,081
Granted
Jun 5, 2018
Kind
B2
Abstract

A secure data parser is provided that may be integrated into any suitable system for securely storing and communicating data. The secure data parser parses data and then splits the data into multiple portions that are stored or communicated distinctly. Encryption of the original data, the portions of data, or both may be employed for additional security. The secure data parser may be used to protect data in motion by splitting original data into portions of data that may be communicated using multiple communications paths.

Claims (45)

1. A method of presenting a virtual disk to a client device, the method comprising:

receiving, using a hardware processor, first client credentials from a first client device, the client credentials including a first client identifier;

authenticating, using the using a hardware processor, the first client device at a secure storage device;

determining, using the using a hardware processor, that a first volume is associated with the first client device based upon the first client identifier, the first volume comprising a directory mapped to a plurality of physical storage devices having stored thereon a first plurality of shares, wherein each of the first plurality of shares comprises a first subset of less than all of first original data, and wherein the first subset in each respective share was rearranged from an original order, and wherein the first plurality of shares includes data indicative of a cryptographic key used to secure the first data;

upon determining that the first volume is associated with the first client device, presenting the first volume to the first client device such that physical locations of the first plurality shares are hidden from the first client device;

receiving, using the hardware processor, second client credentials from a second client device; and

upon determining that a second volume is associated with the second client device, presenting the second volume to the second client device such that physical locations of a second plurality of shares are hidden from the second client device.

2. The method of claim 1 , wherein presenting the volume to the first client includes providing access to data stored in the plurality of shares associated with the volume.

3. The method of claim 1 , further comprising establishing a secure connection between the first client device and the secure storage device.

4. The method of claim 1 , wherein the first plurality of shares contain a substantially random distribution of a unit of data.

5. The method of claim 1 , wherein the unit of data is restorable from at least two shares of the first plurality of shares.

6. The method of claim 5 , further comprising restoring the unit of data from at least two shares of the first plurality of shares, and wherein presenting the first volume to the first client device comprises presenting the restored unit of data.

7. The method of claim 1 , further comprising storing the different keys on a key management server.

8. A secure storage system comprising a programmable circuit configured to execute program instructions which, when executed, configure the secure storage system to:

receive first client credentials from a first client device, the first client credentials including a first client identifier;

authenticate the first client device at a secure storage device;

determine that a first volume is associated with the first client device based upon the first client identifier, the first volume comprising a directory mapped to a plurality of physical storage devices having stored thereon a first plurality of shares, wherein each of the first plurality of shares comprises a subset of less than all of original data, and wherein the subset in each respective share was rearranged from an original order, and wherein the first plurality of shares includes data indicative of a cryptographic key used to secure the first data;

upon determining that the first volume is associated with the first client device, present the first volume to the first client device such that physical locations of the first polarity of shares are hidden from the first client device;

receive, using the hardware processor, second client credentials from a second client device; and

upon determining that a second volume is associated with the second client device, present the second volume to the second client device such that physical locations of a second plurality of shares are hidden from the second client device.

9. The secure storage system of claim 8 , wherein the secure storage system is further configured to provide access to data stored in the first plurality of shares associated with the first volume.

10. The secure storage system of claim 8 , wherein the secure storage system is further configured to establish a secure connection between the first client device and the secure storage system.

11. The secure storage system of claim 8 , wherein the first plurality of shares contain a substantially random distribution of a unit of data.

12. The secure storage system of claim 8 , wherein the unit of data is restorable from at least two shares of the first plurality of shares.

13. The secure storage system of claim 12 , wherein the program instructions further configure the secure storage system to restore the unit of data from at least two shares of the first plurality of shares, and wherein the secure storage system is configured to present the first volume to the first client device by presenting the restored unit of data.

14. The secure storage system of claim 8 , further comprising a key management server configured to store the different keys.

15. A non-transitory computer readable medium storing computer executable instructions that, when executed by at least one processor, cause a computer system to carry out a method for presenting a virtual disk to a client device, the method comprising:

receiving first client credentials from a first client device, the first client credentials including a first client identifier;

authenticating the first client device at a secure storage device;

determining that a first volume is associated with the first client device based upon the first client identifier, the first volume comprising a directory mapped to a plurality of physical storage devices having stored thereon a first plurality of shares, wherein each of the first plurality of shares comprises a subset of less than all of original data, and wherein the subset in each respective share was rearranged from an original order, and wherein the first plurality of shares includes data indicative of a cryptographic key used to secure the first data;

upon determining that the first volume is associated with the first client device, presenting the first volume to the first client device such that physical locations of the first plurality of shares are hidden from the first client device;

receiving, using the hardware processor, second client credentials from a second client device; and

upon determining that a second volume is associated with the second client device, presenting the second volume to the second client device such that physical locations of a second plurality of shares are hidden from the second client device.

16. The non-transitory computer readable medium of claim 15 , wherein presenting the first volume to the first client devices includes providing access to data stored in the first plurality of shares associated with the first volume.

17. The non-transitory computer readable medium of claim 15 , wherein the instructions further comprise establishing a secure connection between the first client device and the secure storage device.

18. The non-transitory computer readable medium of claim 15 , wherein the first plurality of shares contain a substantially random distribution of a unit of data.

19. The non-transitory computer readable medium of claim 15 , wherein the unit of data is restorable from at least two shares of the first plurality of shares.

20. The non-transitory computer readable medium of claim 19 , wherein the instructions further comprise restoring the unit of data from at least two shares of the plurality of shares, and wherein presenting the first volume to the first client device comprises presenting the restored unit of data.

21. The non-transitory computer readable medium of claim 15 , wherein the instructions further comprise storing the different keys on a key management server.

22. The method of claim 1 , wherein the first plurality of shares include data indicative of a cryptographic key used to secure the original data.

23. The secure storage system of claim 8 , wherein the first plurality of shares include data indicative of a cryptographic key used to secure the original data.

24. The non-transitory computer readable medium of claim 15 , wherein the first plurality of shares include data indicative of a cryptographic key used to secure the original data.

25. The method of claim 1 , wherein the subset was rearranged using at least one of a deterministic technique, a random technique, and pseudo-random technique.

26. The secure storage system of claim 8 , wherein the subset was rearranged using at least one of a deterministic technique, a random technique, and pseudo-random technique.

27. The non-transitory computer readable medium of claim 15 , wherein the subset was rearranged using at least one of a deterministic technique, a random technique, and pseudo-random technique.

Assignments (5)
RELEASE OF SECURITY INTEREST Recorded Sep 30, 2022
From: GYENES, ANDY; AUBER INVESTMENTS LTD.; SIMONS, BARBARA; BLT1 C/O FAMILY OFFICE SOLUTIONS; O'REILLY, COLIN; COOPER ROAD LLC.; COYDOG FOUNDATION C/O FAMILY OFFICE SOLUTIONS; DASA INVESTMENTS LLC C/O FAMILY OFFICE SOLUTIONS; LAKOFF, DAVID E.; LEES, DAVID; O'REILLY, DAVID; OKST, DAVID; KEHLER, DEAN C.; KOBAK, DOROTHY; CRAWFORD, ELIZABETH; ALTMANN, ERIC; JOR, GERALD R, JR.; GRANDPRIX LIMITED C/O LOEB BLOCK & PARTNERS L.P.; RAUTENBERG, H.W.; HARPEL, JAMES W.; WU, JASPER; PEISACH, JAIME; LG MANAGEMENT LLC.; LTE PARTNERS; RAUTENBERG, MARK; PINTO, MAURICE; MEYTHALER INVESTMENT PARTNERS LLC; MASELLI, MICHAEL; GYENES, PETER; GINTHER, RAYMOND; BERKELEY, RICHARD M.; MERCER, ROBERT; ROLA INVESTMENTS LLC C/O FAMILY OFFICE SOLUTIONS; SOS & CO.; BARLE, STANKO; STRAUS, SANDOR; MIROCHNIKOFF, SYLVAIN; MERCER, REBEKAH; TOPSPIN SFC HOLDINGS LLC.; BARTON, WESLEY W.; ZUG VENTURES LLC C/O KATHY COOK, FUSION GROUP; ZUCKER, CHARLES; COLEMAN, ROGER T.; COLEMAN, MARGARET E.; COLEMAN, THERESA M.; COLEMAN, JOHN T.; PERLBINDER, STEPHEN
To: SECURITY FIRST CORP.
Reel/Frame 061578/0505 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2022
From: SECURITY FIRST CORP
To: SECURITY FIRST INNOVATIONS, LLC
Reel/Frame 061262/0865 →
PATENT SECURITY AGREEMENT Recorded Jun 24, 2016
From: SECURITY FIRST CORP.
To: GYENES, ANDY; AUBER INVESTMENTS LTD.; SIMONS, BARBARA; BLT1; O'REILLY, COLIN; COOPER ROAD LLC; COYDOG FOUNDATION; DASA INVESTMENTS LLC; LAKOFF, DAVID E; LEES, DAVID; O'REILLY, DAVID; OKST, DAVID; KEHLER, DEAN C; KOBAK, DOROTHY; CRAWFORD, ELIZABETH; ALTMANN, ERIC; JORDAN, GERALD R, JR; GRANDPRIX LIMITED; RAUTENBERG, H.W.; HARPEL, JAMES W.; WU, JASPER; PEISACH, JAIME; LG MANAGEMENT LLC; LTE PARTNERS; RAUTENBERG, MARK; PINTO, MAURICE; MEYTHALER INVESTMENT PARTNERS LLC; MASELLI, MICHAEL; GYENES, PETER; GINTHER, RAYMOND; BERKELEY, RICHARD M; MERCER, ROBERT; ROLA INVESTMENTS LLC; SOS & CO.; BARLE, STANKO; STRAUS, SANDOR; MIROCHNIKOFF, SYLVAIN; MERCER, REBEKAH; TOPSPIN SFC HOLDINGS LLC; BARTON, WESLEY W; ZUG VENTURES LLC; ZUCKER, CHARLES; COLEMAN, ROGER T.; COLEMAN, MARGARET E.; COLEMAN, THERESA M.; COLEMAN, JOHN T.; PERLBINDER, STEPHEN
Reel/Frame 039153/0321 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TYPOGRAPHICAL ERRORS IN ASSIGNEE'S STREET AND CITY ADDRESS PREVIOUSLY RECORDED ON REEL 030590 FRAME 0803. ASSIGNOR(S) HEREBY CONFIRMS THE CORRECTIONS TO ASSIGNEE STREET AND CITY ADDRESS. Recorded Jun 13, 2013
From: ORSINI, RICK L.; O'HARE, MARK S.; DAVENPORT, ROGER; WINICK, STEVEN
To: SECURITY FIRST CORP.
Reel/Frame 030610/0332 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 11, 2013
From: ORSINI, RICK L.; O'HARE, MARK S.; DAVENPORT, ROGER; WINICK, STEVEN
To: SECURITY FIRST CORP.
Reel/Frame 030590/0803 →